Preview ssh as the derived filter admits it, and say a narrowing to the private network closes (hq ADR 0100)

This commit is contained in:
2026-09-22 18:00:53 +02:00
parent ade6b2bfb6
commit 3dc7d0e386
2 changed files with 106 additions and 23 deletions
+44 -12
View File
@@ -217,7 +217,9 @@ func converge(ctx context.Context, open *stores, node string, yes bool, filter s
if err != nil {
return "", err
}
preview := previewOf(node, reported, rules, with.Foundation, plan, taken, filter, runs[filter])
derived := derivedFilter{rules: rules, foundation: with.Foundation, mesh: with.Mesh,
outward: plan.PublicDomain != ""}
preview := previewOf(node, reported, derived, plan, taken, filter, runs[filter])
if !yes {
return preview + fmt.Sprintf("\n\nNothing has changed. Run `converge %s --yes` to do it.", node), nil
}
@@ -252,7 +254,7 @@ func converge(ctx context.Context, open *stores, node string, yes bool, filter s
}
// previewOf is what converging a node will change, before it changes it.
func previewOf(node string, reported inventory.Adoption, rules []catalogue.Rule, foundation []int,
func previewOf(node string, reported inventory.Adoption, derived derivedFilter,
plan catalogue.Resolution, taken []string, filter string, filterAssigned bool) string {
var b strings.Builder
fmt.Fprintf(&b, "converging %s\n", node)
@@ -269,7 +271,7 @@ func previewOf(node string, reported inventory.Adoption, rules []catalogue.Rule,
if r.Published {
what += fmt.Sprintf(" (published, container port %d)", r.ContainerPort)
}
fmt.Fprintf(&b, " %-44s %s\n", what, fate(r, rules, foundation))
fmt.Fprintf(&b, " %-44s %s\n", what, derived.fate(r))
}
if len(reported.Reachable) == 0 {
b.WriteString(" nothing reported\n")
@@ -317,26 +319,56 @@ func previewOf(node string, reported inventory.Adoption, rules []catalogue.Rule,
return strings.TrimRight(b.String(), "\n")
}
// derivedFilter is what the filter the flip loads is rendered from, as AsNftables renders it.
type derivedFilter struct {
rules []catalogue.Rule
foundation []int
// mesh is every address on the private network; outward says the machine faces outside.
mesh []string
outward bool
}
// closesOutside is what a narrowing from everywhere to the private network is called: it closes.
const closesOutside = "WILL CLOSE to everything outside the private network"
// fate is what the derived filter does to one reachable thing: which module declares it and from
// where, or that it will close.
func fate(r inventory.Reach, rules []catalogue.Rule, foundation []int) string {
// where, or that it will close — wholly, or to everything outside the private network. Rendered
// exactly as AsNftables admits it, ssh included.
func (d derivedFilter) fate(r inventory.Reach) string {
// Bound to an address on the private network, it was never reachable from outside it, so
// admitting it from the mesh narrows nothing.
onMesh := slices.Contains(d.mesh, strings.Trim(r.Address, "[]"))
if r.Protocol == "tcp" && r.Port == catalogue.SSHPort {
return "stays open — ssh is never closed"
// From everywhere only when the machine faces outward or the mesh has no addresses to
// narrow it to; otherwise from the private network only.
if d.outward || len(d.mesh) == 0 || onMesh {
return "stays open — ssh is never closed"
}
return closesOutside + " — ssh stays open from the mesh, never closed there"
}
for _, port := range foundation {
for _, port := range d.foundation {
if r.Protocol == "tcp" && r.Port == port {
return "stays open — the mesh's own, from anywhere"
}
}
for _, rule := range rules {
for _, rule := range d.rules {
if rule.Port != r.Port || rule.Protocol != r.Protocol {
continue
}
if rule.From == catalogue.FromMachine {
return fmt.Sprintf("WILL CLOSE to the network — declared by %s for this machine only",
strings.Join(rule.Because, ", "))
by := strings.Join(rule.Because, ", ")
switch rule.From {
case catalogue.FromMachine:
return fmt.Sprintf("WILL CLOSE to the network — declared by %s for this machine only", by)
case catalogue.FromMesh:
if len(d.mesh) == 0 {
return fmt.Sprintf("WILL CLOSE — declared by %s from the mesh, and this node "+
"knows no mesh addresses", by)
}
if !onMesh {
return fmt.Sprintf("%s — declared by %s from the mesh only", closesOutside, by)
}
}
return fmt.Sprintf("declared by %s (from %s)", strings.Join(rule.Because, ", "), rule.From)
return fmt.Sprintf("declared by %s (from %s)", by, rule.From)
}
return "WILL CLOSE — no module assigned here declares it"
}